PluginProbe
The WP Remote WordPress Plugin / 5.88
The WP Remote WordPress Plugin v5.88
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +173 -46 4.875.88 View file →
@@ -4,10 +4,12 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 4.87
8 +Version: 5.88
9 9 Network: True
10 +License: GPLv2 or later
11 +License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
10 12 */
11 13
12 14 /* Copyright 2017 WP Remote (email : support@wpremote.com)
13 15
@@ -36,8 +38,13 @@
36 38 require_once dirname( __FILE__ ) . '/wp_api.php';
37 39 require_once dirname( __FILE__ ) . '/wp_actions.php';
38 40 require_once dirname( __FILE__ ) . '/info.php';
39 41 require_once dirname( __FILE__ ) . '/account.php';
42 +require_once dirname( __FILE__ ) . '/helper.php';
43 +require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
44 +
45 +require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
46 +
40 47 ##WPCACHEMODULE##
41 48
42 49
43 50 $bvsettings = new WPRWPSettings();
@@ -52,18 +59,22 @@
52 59 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
53 60 register_activation_hook(__FILE__, array($wp_action, 'activate'));
54 61 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
55 62
63 +
56 64 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
57 -add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
65 +add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
66 +
58 67 ##SOADDUNINSTALLACTION##
59 68
69 +##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
70 +
60 71 ##WPCLIMODULE##
61 72 if (is_admin()) {
62 73 require_once dirname( __FILE__ ) . '/wp_admin.php';
63 74 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
64 75 add_action('admin_init', array($wpadmin, 'initHandler'));
65 - add_filter('all_plugins', array($wpadmin, 'initBranding'));
76 + add_filter('all_plugins', array($wpadmin, 'initWhitelabel'));
66 77 add_filter('plugin_row_meta', array($wpadmin, 'hidePluginDetails'), 10, 2);
67 78 add_filter('debug_information', array($wpadmin, 'handlePluginHealthInfo'), 10, 1);
68 79 if ($bvsiteinfo->isMultisite()) {
69 80 add_action('network_admin_menu', array($wpadmin, 'menu'));
@@ -71,8 +82,9 @@
71 82 add_action('admin_menu', array($wpadmin, 'menu'));
72 83 }
73 84 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
74 85 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
86 + ##POPUP_ON_DEACTIVATION##
75 87 add_action('admin_notices', array($wpadmin, 'activateWarning'));
76 88 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
77 89 ##ALPURGECACHEFUNCTION##
78 90 ##ALADMINMENU##
@@ -77,12 +89,20 @@
77 89 ##ALPURGECACHEFUNCTION##
78 90 ##ALADMINMENU##
79 91 }
80 92
81 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
82 - $_REQUEST = array_merge($_GET, $_POST);
93 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
94 + $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
83 95 }
84 96
97 +#Service active check
98 +if ($bvinfo->config != false) {
99 + add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
100 +}
101 +
102 +require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
103 +WPRWPPHPErrorMonitoring::init();
104 +
85 105 if ($bvinfo->hasValidDBVersion()) {
86 106 if ($bvinfo->isServiceActive('activity_log')) {
87 107 require_once dirname( __FILE__ ) . '/wp_actlog.php';
88 108 $bvconfig = $bvinfo->config;
@@ -89,74 +109,168 @@
89 109 $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
90 110 $actlog->init();
91 111 }
92 112
113 + if ($bvinfo->isServiceActive('maintenance_mode')) {
114 + require_once dirname( __FILE__ ). '/maintenance/wp_maintenance.php';
115 + $bvconfig = $bvinfo->config;
116 + $maintenance = new BVWPMaintenance($bvconfig['maintenance_mode']);
117 + $maintenance->init();
118 + }
119 +
93 120 }
94 121
95 -if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
122 +if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
96 123 require_once dirname( __FILE__ ) . '/callback/base.php';
97 124 require_once dirname( __FILE__ ) . '/callback/response.php';
98 125 require_once dirname( __FILE__ ) . '/callback/request.php';
99 126 require_once dirname( __FILE__ ) . '/recover.php';
100 127
101 - $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
128 + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized, WordPress.Security.NonceVerification.Recommended
129 + $pubkey = isset($_REQUEST['pubkey']) ? WPRAccount::sanitizeKey(wp_unslash($_REQUEST['pubkey'])) : '';
102 130
103 - if (array_key_exists('rcvracc', $_REQUEST)) {
131 + if (array_key_exists('rcvracc', $_REQUEST)) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
104 132 $account = WPRRecover::find($bvsettings, $pubkey);
105 133 } else {
106 134 $account = WPRAccount::find($bvsettings, $pubkey);
107 135 }
108 136
109 - $request = new BVCallbackRequest($account, $_REQUEST);
137 + $request = new BVCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
110 138 $response = new BVCallbackResponse($request->bvb64cksize);
111 139
112 - if ($account && (1 === $account->authenticate($request))) {
113 - define('WPRBASEPATH', plugin_dir_path(__FILE__));
140 + if ($request->authenticate() === 1) {
141 + if (array_key_exists('bv_ignr_frm_cptch', $_REQUEST)) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
142 + #handling of Contact Forms 7
143 + add_filter('wpcf7_skip_spam_check', '__return_true', PHP_INT_MAX, 2);
114 144
145 + #handling of Formidable plugin
146 + add_filter('frm_is_field_hidden', '__return_true', PHP_INT_MAX, 3);
115 147
116 - require_once dirname( __FILE__ ) . '/callback/handler.php';
148 + #handling of WP Forms plugin
149 + add_filter('wpforms_process_bypass_captcha', '__return_true', PHP_INT_MAX, 3);
117 150
118 - $params = $request->processParams($_REQUEST);
119 - if ($params === false) {
120 - $resp = array(
121 - "account_info" => $account->info(),
122 - "request_info" => $request->info(),
123 - "bvinfo" => $bvinfo->info(),
124 - "statusmsg" => "BVPRMS_CORRUPTED"
125 - );
126 - $response->terminate($resp);
151 + #handling of Forminator plugin
152 + if (defined('WP_PLUGIN_DIR')) {
153 + $abstractFrontActionFilePath = WP_PLUGIN_DIR . '/forminator/library/abstracts/abstract-class-front-action.php';
154 + $frontActionFilePath = WP_PLUGIN_DIR . '/forminator/library/modules/custom-forms/front/front-action.php';
155 +
156 + if (file_exists($abstractFrontActionFilePath) && file_exists($frontActionFilePath)) {
157 + require_once $abstractFrontActionFilePath;
158 + require_once $frontActionFilePath;
159 + if (class_exists('Forminator_CForm_Front_Action')) {
160 + Forminator_CForm_Front_Action::$hidden_fields[] = "bv-stripe-";
161 + }
162 + }
163 + }
164 +
165 + #handling of CleanTalk Antispam plugin
166 + add_action('init', function() {
167 + global $apbct;
168 + if (isset($apbct) && is_object($apbct)) {
169 + $apbct->settings['forms__contact_forms_test'] = 0;
170 + }
171 + });
172 +
173 + #handling of Akismet plugin
174 + add_filter('akismet_get_api_key', function($api_key) { return null; }, PHP_INT_MAX);
175 +
176 + #handling of Formidable Antispam
177 + add_filter('frm_validate_entry', function($errors, $values, $args) {
178 + unset($errors['spam']); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
179 + return $errors;
180 + }, PHP_INT_MAX, 3);
181 +
182 + #handling of Gravity Form plugin
183 + if (isset($_REQUEST['form_id'])) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
184 + $form_id = sanitize_text_field(wp_unslash($_REQUEST['form_id'])); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
185 + add_filter('gform_pre_validation_' . $form_id, function($form) {
186 + foreach ($form['fields'] as &$field) {
187 + if ($field['type'] === 'captcha') {
188 + $field->visibility = 'hidden';
189 + }
190 + }
191 + return $form;
192 + }, PHP_INT_MAX, 1);
193 + }
194 +
195 + #handling of Ninja Form plugin
196 + add_filter('ninja_forms_pre_validate_field_settings', function($field_settings) {
197 + if (isset($field_settings['type']) && in_array($field_settings['type'], array('recaptcha', 'spam'), true)) {
198 + $field_settings['type'] = null;
199 + }
200 +
201 + return $field_settings;
202 + }, PHP_INT_MAX, 1);
203 +
204 + add_filter('ninja_forms_run_action_type_recaptcha', '__return_false', PHP_INT_MAX);
127 205 }
128 - $request->params = $params;
129 - $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
130 - if ($request->is_afterload) {
131 - add_action('wp_loaded', array($callback_handler, 'execute'));
132 - } else if ($request->is_admin_ajax) {
133 - add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
134 - add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
135 - } else {
136 - $callback_handler->execute();
206 +
207 + if (array_key_exists('bv_ignr_eml', $_REQUEST)) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
208 + #handling of Gravity Form's Email
209 + add_filter('gform_pre_send_email', function($email_data) {
210 + $email_data['abort_email'] = true;
211 + return $email_data;
212 + }, PHP_INT_MAX, 1);
213 +
214 + #handling of Ninja Form's Email
215 + add_filter('ninja_forms_action_email_send', '__return_true', PHP_INT_MAX);
216 +
217 + #handling of Contact Form 7's Email
218 + add_action('wpcf7_before_send_mail', function($contact_form, &$abort) { $abort = true; }, PHP_INT_MAX, 2);
219 +
220 + #handling of WP Form's Email
221 + add_filter('wpforms_entry_email', '__return_false', PHP_INT_MAX);
222 +
223 + #handling of Formidable Form's Email
224 + add_filter('frm_send_email', '__return_false', PHP_INT_MAX);
225 +
226 + #handling of Forminator Form's Email
227 + foreach (['poll', 'quiz', 'form'] as $type) {
228 + add_filter("forminator_{$type}_get_admin_email_recipients", function() {
229 + return [];
230 + }, PHP_INT_MAX);
231 + }
137 232 }
233 +
234 + if (!array_key_exists('bv_ignr_frm_cptch', $_REQUEST) && !array_key_exists('bv_ignr_eml', $_REQUEST)) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
235 + define('WPRBASEPATH', plugin_dir_path(__FILE__));
236 +
237 +
238 + require_once dirname( __FILE__ ) . '/callback/handler.php';
239 +
240 + $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
241 + if ($params === false) {
242 + $response->terminate($request->corruptedParamsResp());
243 + }
244 + $request->params = $params;
245 + $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
246 + if ($request->is_afterload) {
247 + add_action('wp_loaded', array($callback_handler, 'execute'));
248 + } else if ($request->is_admin_ajax) {
249 + add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
250 + add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
251 + } else {
252 + $callback_handler->execute();
253 + }
254 + }
138 255 } else {
139 - $resp = array(
140 - "account_info" => $account ? $account->info() : array("error" => "ACCOUNT_NOT_FOUND"),
141 - "request_info" => $request->info(),
142 - "bvinfo" => $bvinfo->info(),
143 - "statusmsg" => "FAILED_AUTH",
144 - "api_pubkey" => substr(WPRAccount::getApiPublicKey($bvsettings), 0, 8),
145 - "def_sigmatch" => substr(WPRAccount::getSigMatch($request, WPRRecover::getDefaultSecret($bvsettings)), 0, 8)
146 - );
147 - $response->terminate($resp);
256 + $response->terminate($request->authFailedResp());
148 257 }
149 258 } else {
150 259 if ($bvinfo->hasValidDBVersion()) {
151 260 if ($bvinfo->isProtectModuleEnabled()) {
152 - require_once dirname( __FILE__ ) . '/protect/wp/protect.php';
153 - $bvprotect = new BVProtect($bvdb, $bvsettings);
154 - $bvprotect->init();
155 - if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
156 - $bvprotect->run();
261 + require_once dirname( __FILE__ ) . '/protect/protect.php';
262 + //For backward compatibility.
263 + WPRProtect_V588::$settings = new WPRWPSettings();
264 + WPRProtect_V588::$db = new WPRWPDb();
265 + WPRProtect_V588::$info = new WPRInfo(WPRProtect_V588::$settings);
266 +
267 + add_action('wpr_clear_pt_config', array('WPRProtect_V588', 'uninstall'));
268 +
269 + if ($bvinfo->isActivePlugin()) {
270 + WPRProtect_V588::init(WPRProtect_V588::MODE_WP);
271 + }
157 272 }
158 - }
159 273
160 274 if ($bvinfo->isDynSyncModuleEnabled()) {
161 275 require_once dirname( __FILE__ ) . '/wp_dynsync.php';
162 276 $bvconfig = $bvinfo->config;
@@ -189,5 +303,18 @@
189 303 if (is_admin()) {
190 304 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
191 305 }
192 306
193 -}
307 + ##THIRDPARTYCACHINGMODULE##
308 +}
309 +
310 +if (WPRWP2FA::isEnabled($bvsettings)) {
311 + $wp_2fa = new WPRWP2FA();
312 + $wp_2fa->init();
313 +}
314 +
315 +if (!empty($bvinfo->getLPWhitelabelInfo())) {
316 + $wp_login_whitelabel = new WPRWPLoginWhitelabel();
317 + $wp_login_whitelabel->init();
318 +}
319 +
320 +add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));